Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 12-Jul-05, at 8:40 AM, Bob Puff wrote:

> I specifically purchased CS3.0 for this exact reason - so I  
> wouldn't have to
> worry about building stuff from sources each time there was an update.

You bought CS3 so that you would get the latest version of package  
xyz while everyone else was getting a patched version?  I feel sorry  
for you, Bob.  Either someone suckered you or you just plain old  
misunderstood what the extra life support in CS3 was all about (which  
is odd because nowhere can I see CS3 or CD3 being advertised as  
getting the latest versions of stuff while other people get patches).

> I understand the logic in not doing upgrades that would break  
> something else,
> but packages like clamav, spamassassin, and amavis are extremely  
> important to
> have updated to the latest version, and I think they need to be an  
> exception.

I'm glad you think that, but unfortunately we disagree and that's not  
policy.  Spamassassin was a different story... the only reason it got  
updated to the latest version recently was because the SA team  
refused to give patches and to give us enough info to properly  
extract a patchset.  You'll note that doesn't happen very often *at  
all* because it goes against a policy that was established *years*  
ago.  You'll also note that every single other distribution does the  
same thing, so it's not like we're being anal or something.

> Right now, I am indeed disappointed that an update was done that  
> was probably
> more work to have done the back-ports than to simply give the  
> latest version,
> that is not useful to the paying community.

Actually, it was pretty easy and I can guarantee that upgrading the  
software would have been problematic, but thanks for trying.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.